Refi Hub co-founder Numa Lunah said he was hacked after installing a transcription app through a download link provided in a Claude chat window. According to ChainCatcher, the link led to a spoofed website bundled with malware that attempted to steal all information on his device.
Lunah said he wiped and reinstalled the laptop involved and found no evidence that sensitive information had been leaked. He later found a compromised Claude Code skill file, SKILL.md, in his backups. The file was disguised as a style guide he had written and included instructions to redownload malware each time it loaded and steal credentials.
Microsoft Defender Experts had previously warned that attackers are shifting from search engine optimization poisoning to large language model answer poisoning. The tactics include recommending attacker-controlled download links, AI-branded fake installers, and compromised code repositories and agent skills. The article said crypto industry workers may hold irreversible credentials such as seed phrases, private key files, hot wallet JSON files, exchange API keys with withdrawal permissions, and deployer keys.